Risk profiling, a visual discussion

stick_figures_reporting_to_manager_400_clr_9595Risk profiling needs to move to a visual discussion.

Risk profiling practices of today are generally text based and focused on developing risks around words and sentences to represent the risk, controls and actions.  Yet research by 3M, highlighted in this blog post,  “concluded that we process visuals 60,000 times faster than text. Further studies find that the human brain deciphers image elements simultaneously, while language is decoded in a linear, sequential manner taking more time to process.”

So why is it we persist with representing risks to people in a non-visual manner.  In particular, why do we revert to non-visual methods in the process of performing the risk assessments and then in the initial representation of risks?  Of course, most people will report on components of risk profiling using charts and visual tools, but the process itself of performing the risk assessment will generally be “words” focused.

Of course a visual approach has risks.  How can a visual truly represent a risk?  People may interpret visuals very differently, how do we know everyone is thinking the same thing?  But I challenge you that even with text, this risks exist.

Here is a little visual exercise for you.  Try and guess what risks these visuals represent.

thief_stealing_credit_card_400_clr_7276

creating_a_better_process_400_clr_7366

radiation_expert_paranoid_400_clr_8948

walking_debt_chain_ball_400_clr_10149

How did you do?  Print this page and show 3 colleagues and see what they guess these risks to be.

There will be differences, for instance the first one could be credit card fraud, fraud, theft, or even breach of privacy.  Interestingly these are all essentially similar risk themes, therefore even though there are variances, the variances do not cause the risk assessment process to degrade. For the process orientated reader, the other 3 pictures are process failures or problems, environmental hazards, and financial risk.

Once you have completed the “survey” of your colleagues with the visual risks.  Provide them written risk statements and ask them to explain the risk to you.  What differences do you see in the responses?

Now ask them to rate which they prefer in regards to documenting risks.

The Power of Visual Communication highlights that, “How many times have you heard, “I didn’t believe it until I saw it.” Studies show that the old saying “seeing is believing” is mostly true. Of course, we know that what we see can be manipulated but the point is that visuals are persuasive. The Stanford Persuasive Technology Lab asked 2,440 participants how they evaluated the credibility of Web sites they were shown. Almost half (46.1%) said that the Web site’s design look was the number one criterion for discerning the credibility of the presented material.”

We suspect, that based on your research you may find that a large number of people would prefer the visual cues for discussing risks.  Of course, from a regulatory perspective, visuals are not going to be enough to provide clarity of risk and are also very difficult to populate into existing risk management tools.  Therefore, a balance between the two is required.

The intent of this posting is not to say all risk assessments should use pictures, but rather that thinking differently about risk profiling will provide valuable results to your business and your risk management process.  In particular, ensuring that risk profiling resonates with as many people as possible, through both visual and written means, will provide better business outcomes and a more engaging discussion.

Risk profiling needs to be a visual discussion because people want to be engaged using all mediums possible.  Regardless of their generation.

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.